CVE-2025-27462: WinPVDrivers: Excessive permissions on user-exposed devices
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are:
1. XenCons, CVE-2025-27462 2. XenIface, CVE-2025-27463 3. XenBus, CVE-2025-27464
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27462?
CVE-2025-27462 is classified as a high-severity vulnerability due to its potential impact on user data and system integrity.
How do I fix CVE-2025-27462?
To fix CVE-2025-27462, update your XEN WinPVDrivers to the latest version released by the maintainers that addresses this vulnerability.
What are the risks associated with CVE-2025-27462?
The risks of CVE-2025-27462 include unauthorized access to user-exposed devices and potential data leakage.
Which versions of XEN are affected by CVE-2025-27462?
CVE-2025-27462 affects specific versions of XEN WinPVDrivers, and users should consult the vendor's advisory for the exact versions impacted.
Is there a workaround for CVE-2025-27462?
While the recommended approach is to update, temporarily limiting device access permissions may serve as a workaround for CVE-2025-27462.